# Critical HVAC and UPS Vulnerabilities Expose Data Centers to Remote Disruption Attacks
Claroty researchers have uncovered multiple critical security flaws in widely-deployed infrastructure systems that power data centers worldwide, revealing a dangerous vulnerability chain that could allow attackers to remotely disable cooling systems and power management—potentially causing millions in damage and widespread service outages.
## The Threat
Security researchers at Claroty, a cyber-physical systems specialist, have identified critical vulnerabilities in two essential data center systems:
Vertiv UPS Network Cards:
Trane Tracer SC+ HVAC Controller:
The combination of these vulnerabilities represents a critical risk: an attacker with network access could simultaneously disable both power protection and cooling systems in a data center—a one-two punch that could trigger catastrophic cascading failures.
## Background and Context
The implications of these vulnerabilities extend far beyond a simple system outage. Understanding the role of these systems in data center operations is essential:
Uninterruptible Power Supplies (UPS) serve critical functions:
According to Claroty, "In large data centers, virtually all computing equipment relies on UPS devices to stay online during power issues. Any weakness in those UPS communication modules can directly affect the machines they protect."
HVAC systems are equally vital:
The attack surface is particularly concerning because these devices are typically connected to facility networks—often with minimal network segmentation or monitoring. Many organizations treat environmental controls as non-critical from a cybersecurity perspective, making them attractive targets for attackers seeking to disrupt operations without triggering traditional security alerts.
## Technical Details
The Vertiv Attack Chain:
The vulnerability chain in Vertiv's network cards works as follows:
1. Authentication Bypass — The web interface protecting UPS management functions fails to properly validate credentials, allowing unauthorized access to administrative features
2. Remote Code Execution — Once inside, attackers can execute arbitrary commands on the network card itself
3. Operational Impact — Full control of the UPS enables attackers to:
- Disable power protection for connected equipment
- Trigger emergency shutdown sequences
- Manipulate power distribution to specific equipment
- Alter monitoring and alerting systems
The Trane HVAC Vulnerabilities:
The Trane Tracer SC+ controller exhibits a similar pattern but with even broader implications:
| Vulnerability | Impact | Severity |
|---|---|---|
| Authentication Bypass | Unauthenticated administrative access | Critical |
| Remote Code Execution | Full system compromise | Critical |
| Information Disclosure | Exposure of building layout, sensor data, configurations | High |
| Denial of Service | System crashes or resource exhaustion | High |
Claroty emphasized that "data center servers generate enormous amounts of heat, and an HVAC failure is far more than a comfort issue. It can trigger thermal shutdowns, damage expensive hardware, cause major service disruptions, and lead to millions of dollars in losses."
## Implications for Organizations
Immediate Risks:
Attack Scenarios:
A realistic attack progression might look like this:
1. Attacker gains initial network access through phishing or vulnerable web services
2. Reconnaissance identifies Vertiv or Trane devices on facility network
3. Authentication bypass exploits provide immediate administrative access
4. Attacker executes code to disable HVAC or alter UPS behavior
5. Equipment thermal shutdown or power loss cascades across facility
6. Extended recovery period impacts business operations
The financial impact could be severe: major data center outages cost $5,600 per minute to large enterprises, meaning even a 30-minute incident could exceed $168,000 in damages, not accounting for lost reputation and customer churn.
## Recommendations for Defenders
Immediate Actions:
Strategic Controls:
---
## HackWire Analysis
This vulnerability disclosure represents a troubling pattern in industrial control system security: attackers have increasingly recognized that environmental controls offer a path to operational disruption that bypasses traditional network security. Unlike applications that require user interaction to exploit, HVAC and power systems sit passively on facility networks, often overlooked in security assessments.
What makes this moment particularly critical is the convergence of automation and underestimation. Data center operators have grown accustomed to thinking of cooling and power as solved problems—ancient infrastructure that "just works." But the digitization of these systems has created a new attack surface that most organizations haven't adequately secured. The default web interfaces, the legacy authentication schemes, and the assumption that "no one would target these systems"—this is exactly where attackers focus.
Consider the broader context: we've seen ransomware groups target hospital HVAC systems, criminal syndicates compromise building management systems in corporate headquarters, and nation-state actors conduct reconnaissance on critical infrastructure SCADA systems. This research from Claroty suggests those patterns aren't aberrations—they're reconnaissance for what might come next.
For defenders, the concrete next steps are clear: treat environmental controls with the same security rigor as your production systems. These aren't comfort features—they're availability features. A facility without cooling isn't a facility; it's a fire hazard. Organizations should begin with a simple inventory: identify every Vertiv and Trane device in your environment, verify patch status, and implement network segmentation. The vendors have provided patches; organizations now have the tools to protect themselves. The question is whether they'll act before attackers do.
— HackWire Editorial
---
## Related Coverage